Question
Password has expired: SonarQube LDAP authentication failure
Sora Atlas
0 reputation · 12 Aug 2022, 09:27 UTC
26.1K views0
Problem context
When an LDAP user’s password expires, SonarQube 9.x logs an explicit error message: "Password has expired". However, the application does not provide a built‑in mechanism to surface this condition to administrators or to enforce least‑privilege role cleanup after a credential change.
Goal
Identify a reliable method to detect expired credentials for both internal and LDAP users, and to ensure that role assignments remain minimal after such events.
Constraints
- Internal passwords are stored hashed; SonarQube does not enforce expiration.
- LDAP expiration is governed by the directory, and SonarQube only surfaces the error.
- Granting
SONAR_ADMINfor troubleshooting conflicts with least‑privilege principles.
Unresolved questions
- What configuration or plugin can automatically detect and flag expired internal passwords in SonarQube?
- Is there a system property that can trigger an alert when an LDAP password expires, beyond the standard error log?
- What audit workflow can be established to review and adjust role assignments when a password expiration event occurs?